<?php
    session_start();
?>
<!DOCTYPE html>
<html>
    <head>
      	<meta charset="utf-8">
        <link rel="stylesheet" type="text/css" href="./style.css">
        <script type="text/javascript"
            src="https://maps.googleapis.com/maps/api/js?
                 key=AIzaSyCsTHUfyC8gRQBvZ3O-SpoFhvKa7OTREwc&sensor=false&language=bg&region=bg&libraries=places,drawing">
        </script>
        <script type="text/javascript" src="./jscript.js"></script>
    </head>
    <body>
        <?php
            if (isset($_SESSION['isadmin']) && $_SESSION['isadmin'] == 'yes') {
                echo '<form method="post" action="logout.php"> <input id="login" type="submit" value="Изход"></button> </form>';
            } else {
                echo '<button id="login" type="button" onclick="loginPrompt()"> Вход </button>';
            }
        ?>
        <h1> Добре дошли на сайта ни! </h1>
        <div id=left>
            <form method="post" action="search.php">
                Търсене <input type="search" size="51" name="search" autocomplete="on" autofocus>
            </form>
            <?php
                if (isset($_GET['gobjId'])) {
                  // we can retrieve its data from the db
                  require_once 'dbvars.php';
                  // Connect to server and select database.
                  $con = new mysqli("$host", "$username", "$password", "$db_name");
                  if ($con->connect_error) {
                    die('Connect Error (' . $con->connect_errno . ') ' . $con->connect_error);
                  }

                  $sql = "Select name, coords, description FROM $gobject_tbl_name WHERE id=".$_GET['gobjId'];

                  $result = $con->query($sql);

                  if ($result->num_rows > 0) {
                    $row = $result->fetch_row();
                    $_SESSION['name'] = $row[0];
                    $_SESSION['coords'] = $row[1];
                    $_SESSION['descr'] = $row[2];
                  }
				  
				  $con->close();
                }
                if (isset($_SESSION['name']) && isset($_SESSION['coords']) && isset($_SESSION['descr'])) {
                    echo '<br/> Име: <div class="formelems">' . $_SESSION['name'] . ' </div>';
                    $coordsarr = explode(',' , $_SESSION['coords']);
                    if ($coordsarr[3]) { //rectangle
                        echo 'Координати център: <div class="formelems">' . $coordsarr[0] . ',' . $coordsarr[1] . ' </div> <br/>';
                        echo 'Координати горен десен ъгъл: <div class="formelems">' . $coordsarr[5] . ',' . $coordsarr[6] . ' </div> <br/>';
                        echo 'Координати долен ляв ъгъл: <div class="formelems">' . $coordsarr[3] . ',' . $coordsarr[4] . ' </div> <br/>';
                    } elseif ($coordsarr[2]) { //circle
                        echo 'Координати център: <div class="formelems">' . $coordsarr[0] . ',' . $coordsarr[1] . ' </div> <br/>';
                        echo 'Радиус: <div class="formelems">' . $coordsarr[2] . ' метра </div> <br/>';
                    } else { //marker
                        echo 'Координати: <div class="formelems">' . $coordsarr[0] . ',' . $coordsarr[1] . ' </div> <br/>';
                    }
                    echo 'Описание: <div class="formelems">' . $_SESSION['descr'] . ' </div> <br/>';
					if (isset($_GET['gobjId'])) {
						  // we can retrieve its data from the db
						  require_once 'dbvars.php';
						  // Connect to server and select database.
						  $con = new mysqli("$host", "$username", "$password", "$db_name");
						  if ($con->connect_error) {
								die('Connect Error (' . $con->connect_errno . ') ' . $con->connect_error);
						  }
						  $sql = "Select id, name from $gobject_tbl_name join $gobjectref_tbl_name on $gobject_tbl_name.id = $gobjectref_tbl_name.referee where $gobjectref_tbl_name.referer=".$_GET['gobjId'];
						  $result = $con->query($sql);
						  if ($result->num_rows > 0) {
								echo 'Виж още: ';
								for($i=0; $i<$result->num_rows - 1; $i++) {
									$row = $result->fetch_row();
									echo '<a href="./selected.php?gobjId='.$row[0].'">'.$row[1].'</a>, ';
								}
								// last row, no comma in the end
								$row = $result->fetch_row();
								echo '<a href="./selected.php?gobjId='.$row[0].'">'.$row[1].'</a>';
						  }
						  $con->close();
					}
                    echo '<input id="hname" type="text" name="name" class="nodis" value="' . $_SESSION['name'] . '"/>
                          <input id="hcoords" type="text" name="coords" class="nodis" value="' . $_SESSION['coords'] . '"/>
                          <input id="hdescr" type="text" name="descr" class="nodis" value="' . $_SESSION['descr'] . '"/>
                          <input id="hhidedraw" type="text" name="hidedraw" class="nodis"/>';
                }
                if (isset($_SESSION['isadmin']) && $_SESSION['isadmin'] == 'yes') {
                    echo '<a href="./add.php"><button id="add" type="button"> Добави обект </button></a>
                          <form method="post" action="select.php">
	                            <input type="hidden" name="gobjId" value="'.$_GET['gobjId'].'"/>
                              <input id="edit" type="submit" name="edit" value="Промени"/>
                              <input id="del" type="submit" name="del" value="Изтрий"/>
                          </form>';
                }
            ?>
        </div>
        <div id="map-canvas"/>
    </body>
</html>